Skip to content

Privacy Policy

Read our privacy policy

1. Data Controller

The website https://www.billoff.com is edited by:

Billoff Solutions Limited (C 116008)

Headquarters:

Email: [email protected]

The company acts as the data controller for personal data collected from users.


2. Purpose of this Policy

This Policy explains how Billoff collects, uses, stores and protects the personal data of its users, in accordance with:

• Regulation (EU) 2016/679 (GDPR) for users located in the European Union;

• Law No. 78-17 amended (Data Protection Act) for France;

• Personal Data Protection Law (PDPL) applicable in the Malta.


3. Data Collected

Billoff collects only the data necessary for the provision, management and billing of its services:

Account data:

Username, encrypted password, subscription history, invoices.

Identification data:

Name, first name, postal address, email address, phone number, country.

Payment data:

Card number and banking information processed only by the Stripe provider; Billoff never has access to it.

Technical data:

IP address, device type, browser, logs, analytical and security cookies.

Data related to service use:

Uploaded documents, created templates, sender and recipient addresses, sending history, mail tracking.


4. Processing Purposes

Data is processed for the following purposes:

  1. Provision and execution of services (creation, printing, sending of mail).
  2. Customer account management and billing.
  3. Fraud prevention and payment security.
  4. Customer assistance and technical support.
  5. Site improvement and service performance.
  6. Compliance with legal obligations (billing, anti-money laundering, accounting records).
  7. Sending administrative or contractual information related to the service.
  8. Managing requests to exercise GDPR/PDPL rights.

5. Legal Basis for Processing

Depending on the situation:

  1. Contract execution (service use, order processing, billing).
  2. Consent (account creation, cookies, marketing).
  3. Legal obligation (record keeping, invoices).
  4. Legitimate interest (fraud prevention, service improvement).

6. Data Retention

Data is retained for the strictly necessary duration:

CategoryMaximum Duration
Account dataas long as account is active + 3 years after deletion
Billing data10 years (accounting obligations)
Sent mail datasubscription duration + 6 months
Technical data / logs12 months
Analytical cookiesmaximum 13 months

Customer documents and files are automatically deleted at the end of the subscription or account closure.


7. Hosting and International Transfers

Data is hosted on secure servers of OVHcloud (OVH SAS)., located in the European Union (Lithuania and Netherlands).

Backups and processing may be carried out in Malta as part of the technical management of the service.

International transfers comply with guarantees provided by GDPR (Standard Contractual Clauses of the European Commission).


8. Data Sharing

Billoff does not sell or rent personal data. Information may be communicated only to:

  1. Technical service providers (hosting, routing, printing, customer support).
  2. Payment providers (Stripe).
  3. Carriers and postal operators for executing shipments.
  4. Administrative or judicial authorities when the law requires it.

All subprocessors are bound by strict confidentiality and security obligations.


9. Security

Billoff applies technical and organizational security measures compliant with international standards: SSL/TLS encryption, password hashing, firewall, logging, environment segregation, strict access control, internal security audits.


10. Cookies

The Site uses cookies:

  1. Technical: essential for service operation.
  2. Analytical (Google Analytics 4): to measure audience.
  3. Functional: to save language and preferences.

The Client can manage cookies via the consent banner or browser settings. Refusing technical cookies may prevent access to the service.


11. User Rights (GDPR / PDPL)

The Client has the following rights:

  1. Right of access to their data.
  2. Right to rectification.
  3. Right to erasure ("right to be forgotten").
  4. Right to restrict processing.
  5. Right to object.
  6. Right to data portability (data export).
  7. Right to set post-mortem directives (EU only).

Any request can be addressed to: [email protected] Response within a maximum of 30 days. An identity document may be requested for verification.


12. Main Processors


13. Transfers Outside the EU

Data may be transferred to Malta for technical and support needs.

Billoff guarantees an equivalent level of protection via Standard Contractual Clauses compliant with Article 46 of the GDPR and the Personal Data Protection Act applicable in Malta.


14. Contact and Complaints

For any questions or to exercise rights: [email protected]

Users located in the European Union may also file a complaint with their national data protection authority.


15. Policy Updates

Billoff reserves the right to modify this policy at any time.

The applicable version is the one published on the website on the date of consultation.

Any substantial modification will be notified by email or through the customer account.


16. Stripe and fraud prevention

We use Stripe for payment, analytics, and other business services. Stripe collects identifying information about the devices that connect to its services. Stripe uses this information to operate and improve the services it provides to us, including for fraud detection. You can learn more about Stripe and read its privacy policy at https://stripe.com/privacy.


How Google uses your data

When you accept advertising and measurement cookies, Google processes your personal data as an independent controller for its own purposes. Google explains those uses, and the choices you have, here: How Google uses data from sites or apps that use its services